mirror of
https://github.com/0xMarcio/cve.git
synced 2025-05-07 03:02:30 +00:00
665 B
665 B
CVE-2019-19210
Description
Dolibarr ERP/CRM before 10.0.3 allows XSS because uploaded HTML documents are served as text/html despite being renamed to .noexe files.
POC
Reference
- https://herolab.usd.de/en/security-advisories/
- https://herolab.usd.de/security-advisories/usd-2019-0052/
Github
No PoCs found on GitHub currently.